Reported October 17, 2002, by
Microsoft.
VERSIONS AFFECTED
·
Microsoft SQL Server 2000
·
Microsoft Desktop Engine (MSDE) 2000
·
Microsoft SQL Server 7.0
·
Microsoft Data Engine (MSDE) 1.0
DESCRIPTION
A vulnerability exists in SQL Server that lets a
low-privileged user run, delete, insert, and update Web tasks.
This vulnerability stems from the fact that the xp_runwebtask stored procedure fails to set permissions
properly when executed and runs under SQL Server's privileges. By default,
PUBLIC users can execute the xp_runwebtask stored procedure, thus allowing
privilege elevation. For more details about this vulnerability, see the
discoverer’s Web
site.
VENDOR RESPONSE
The
vendor, Microsoft, has released Security
Bulletin MS02-061
(Elevation of Privilege in SQL Server Web Tasks) to address this vulnerability
and recommends that affected users apply the appropriate patch mentioned in the
bulletin.
CREDIT
Discovered
by David Litchfield of Next Generation
Security Software Ltd.
End of Article